You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PowerShell请求Azure Databricks访问令牌时遇范围值错误

问题原因及解决方法

核心原因

PowerShell的Invoke-WebRequest在使用哈希表作为-Body参数时,会自动对所有参数值进行URL编码。你在scope中写的%2F是已经编码过的斜杠,会被再次编码成%252F,导致实际发送到AAD的scope值变成2ff814a6-3304-4ab8-85cb-cd0e6f879c1d%252F.default,这不符合AAD要求的资源ID/.default格式(正确编码后应为资源ID%2F.default)。

而curl中的-d参数会直接将字符串作为表单数据发送,%2F不会被二次编码,所以能正常被AAD解析。

解决方案

有两种方式可以解决这个问题:

方案1:使用未编码的斜杠,让PowerShell自动处理编码

直接把scope里的%2F替换成实际的斜杠/,PowerShell会自动将其编码为%2F,符合AAD的要求:

$headers = @{'Content-Type'='application/x-www-form-urlencoded'}
$method = 'POST'
$url = 'https://login.microsoftonline.com/<tenant_id>/oauth2/v2.0/token'
$body = @{
    'client_id'     = '<app_id>'
    'grant_type'    = 'client_credentials'
    'scope'         = '2ff814a6-3304-4ab8-85cb-cd0e6f879c1d/.default'
    'client_secret' = '<app_secret>'
}

Invoke-WebRequest $url -Method $method -Headers $headers -Body $body

方案2:手动构造URL编码的表单字符串,避免自动编码

直接构造完整的URL编码表单字符串作为Body,这样Invoke-WebRequest不会对其进行二次编码:

$headers = @{'Content-Type'='application/x-www-form-urlencoded'}
$method = 'POST'
$url = 'https://login.microsoftonline.com/<tenant_id>/oauth2/v2.0/token'
$body = "client_id=<app_id>&grant_type=client_credentials&scope=2ff814a6-3304-4ab8-85cb-cd0e6f879c1d%2F.default&client_secret=<app_secret>"

Invoke-WebRequest $url -Method $method -Headers $headers -Body $body

内容的提问来源于stack exchange,提问作者Ken

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 05:04:58